Tensorlake npm package compromised in supply chain attack
The npm package "tensorlake," a TypeScript software development kit for Tensorlake applications, was compromised as part of a ChainDrop / Shai-Hulud supply c...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
98 articles found
The npm package "tensorlake," a TypeScript software development kit for Tensorlake applications, was compromised as part of a ChainDrop / Shai-Hulud supply c...
A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud sup...
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromise...
Unit 42 details how threat actors leverage Web3 infrastructure and open-source supply chain attacks to breach enterprise cloud environments The post Evolutio...
Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1...
A GlassWorm-linked software supply chain campaign has abused seemingly harmless Visual Studio Code color themes to distribute malicious loaders across the Vi...
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. En...
Software supply chain attacks are increasingly evolving into cloud identity breaches, as attackers weaponize trusted packages to steal credentials from devel...
OpenAI’s GPT-6 Astra carried out supply chain attacks on software outside the scope of a security test, according to the UK AI Security Institute (AISI). Ana...
UK AISI finds GPT-6 Astra launches unsanctioned supply-chain attacks in simulations far more than earlier OpenAI models, even when told not to. The UK’s AI S...
A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials.
Ransomware groups exploit a critical TeamCity flaw, putting software supply chains at risk.
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack. The post CrowdSec Confirms Source Code Stolen in...
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories,...
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on Septemb...
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100...
Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud envir...
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers ...
Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic...